# Error when loading Google Cloud Storage credentials file

**URL:** <https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370>\
**Category:** Elasticsearch\
**Created:** [July 24, 2017, 5:07pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370 "2017-07-24T17:07:10Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [July 24, 2017, 5:07pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/1 "2017-07-24T17:07:11Z")

</div>

I'm trying to get [Google Cloud Storage Repository Plugin](https://www.elastic.co/guide/en/elasticsearch/plugins/5.5/repository-gcs.html) going:

I installed _repository-gcs_ plugin:

```
# /opt/elasticsearch/bin/elasticsearch-plugin install repository-gcs
-> Downloading repository-gcs from elastic
[=================================================] 100%   
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: plugin requires additional permissions @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
* java.lang.RuntimePermission accessDeclaredMembers
* java.lang.RuntimePermission setFactory
* java.lang.reflect.ReflectPermission suppressAccessChecks
* java.net.URLPermission http://www.googleapis.com/* *:
* java.net.URLPermission https://www.googleapis.com/* *:
See http://docs.oracle.com/javase/8/docs/technotes/guides/security/permissions.html
for descriptions of what these permissions allow and the associated risks.

Continue with installation? [y/N]y
-> Installed repository-gcs
# service elasticsearch restart
 * Stopping Elasticsearch Server [OK] 
 * Starting Elasticsearch Server [OK] 
#

```

I then created a keystore and added the string (per [Secure Settings](https://www.elastic.co/guide/en/elasticsearch/reference/current/secure-settings.html)).

yet while trying to [Create a Repository](https://www.elastic.co/guide/en/elasticsearch/plugins/5.5/repository-gcs-repository.html), I'm getting following error:

```
# curl --silent --request PUT elk:9200/_snapshot/repository-gcs?pretty --data '{"type":"gcs","settings":{"bucket":"repository-gcs","client":"digaweb"}}'
{
  "error" : {
    "root_cause" : [
      {
        "type" : "exception",
        "reason" : "Error when loading Google Cloud Storage credentials file"
      }
    ],
    "type" : "repository_exception",
    "reason" : "[repository-gcs] failed to create repository",
    "caused_by" : {
      "type" : "exception",
      "reason" : "Error when loading Google Cloud Storage credentials file",
      "caused_by" : {
        "type" : "i_o_exception",
        "reason" : "The Application Default Credentials are not available. They are available if running in Google Compute Engine. Otherwise, the environment variable GOOGLE_APPLICATION_CREDENTIALS must be defined pointing to a file defining the credentials. See https://developers.google.com/accounts/docs/application-default-credentials for more information."
      }
    }
  },
  "status" : 500
}
# 

```

I'm _NOT_ running elasticsearch inside of Google Compute Engine, so I defined environment variable _GOOGLE\_APPLICATION\_CREDENTIALS_ , however still getting same error (see above):

```
# export GOOGLE_APPLICATION_CREDENTIALS=/digaweb-c819f0854eae.json 
# echo $GOOGLE_APPLICATION_CREDENTIALS
/digaweb-c819f0854eae.json
# 
# service elasticsearch restart
 * Stopping Elasticsearch Server [OK] 
 * Starting Elasticsearch Server [OK] 
#

```

Please advise.  
Thanks in advance)

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [August 3, 2017, 3:50pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/2 "2017-08-03T15:50:38Z")

</div>

Which version of elasticsearch are you using? What command are you using to add the credentials file to the keystore?

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [August 3, 2017, 8:39pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/3 "2017-08-03T20:39:36Z")

</div>

> [@rjernst](#):
>
> Which version of elasticsearch are you using? What command are you using to add the credentials file to the keystore?

I apologize for not including that information in my topic from the start, but there it is:

elasticsearch:

```
# curl elk:9200
{
  "name" : "linode5",
  "cluster_name" : "digaweb",
  "cluster_uuid" : "DnyG6zP1QYSrC_kBvZzFZQ",
  "version" : {
    "number" : "5.5.0",
    "build_hash" : "260387d",
    "build_date" : "2017-06-30T23:16:05.735Z",
    "build_snapshot" : false,
    "lucene_version" : "6.6.0"
  },
  "tagline" : "You Know, for Search"
}
# 

```

keystore's add:

> cat digaweb-c819f0854eae.json | /opt/elasticsearch/bin/elasticsearch-keystore add --stdin digaweb

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [August 3, 2017, 9:07pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/4 "2017-08-03T21:07:32Z")

</div>

You have two problems. First, the `add` command is for string settings. But GCS requires the entire _file_ be added. Second, you are specifying the setting as `digaweb`, but that is not the setting name GCS looks for.

See the docs for using a service account file:  
[https://www.elastic.co/guide/en/elasticsearch/plugins/master/repository-gcs-usage.html#repository-gcs-using-service-account](https://www.elastic.co/guide/en/elasticsearch/plugins/master/repository-gcs-usage.html#repository-gcs-using-service-account)

I believe your keystore command should look something like this:

```auto
/opt/elasticsearch/bin/elasticsearch-keystore add-file gcs.client.default.credentials_file digaweb-c819f0854eae.json

```

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [August 4, 2017, 4:32pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/5 "2017-08-04T16:32:07Z")

</div>

per @rjernst comment, I ran _elasticsearch-keystore_ with "add-file" instead of "add --stdin":

```
# /opt/elasticsearch/bin/elasticsearch-keystore remove digaweb
# /opt/elasticsearch/bin/elasticsearch-keystore list
# /opt/elasticsearch/bin/elasticsearch-keystore add-file gcs.client.default.credentials_file digaweb-c819f0854eae.json
# echo $?
0
# /opt/elasticsearch/bin/elasticsearch-keystore list
gcs.client.default.credentials_file
# curl --silent --request PUT elk:9200/_snapshot/repository-gcs?pretty --data '{"type":"gcs","settings":{"bucket":"repository-gcs"}}'
{
  "error" : {
    "root_cause" : [
      {
        "type" : "exception",
        "reason" : "Error when loading Google Cloud Storage credentials file"
      }
    ],
    "type" : "repository_exception",
    "reason" : "[repository-gcs] failed to create repository",
    "caused_by" : {
      "type" : "exception",
      "reason" : "Error when loading Google Cloud Storage credentials file",
      "caused_by" : {
        "type" : "i_o_exception",
        "reason" : "The Application Default Credentials are not available. They are available if running in Google Compute Engine. Otherwise, the environment variable GOOGLE_APPLICATION_CREDENTIALS must be defined pointing to a file defining the credentials. See https://developers.google.com/accounts/docs/application-default-credentials for more information."
      }
    }
  },
  "status" : 500
}
#

```

Please advise)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2017, 4:32pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/6 "2017-09-01T16:32:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 11, 2017, 9:16pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/7 "2017-09-11T21:16:33Z")

</div>



---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [September 11, 2017, 9:25pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/8 "2017-09-11T21:25:13Z")

</div>

It looks like you are adding the setting to the keystore, but not restarting elasticsearch. The keystore is only read on elasticsearch startup.

---

<div class="post-metadata">

**Author:** ![erroneousboat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/erroneousboat/32/22325_2.png) [@erroneousboat](https://discuss.elastic.co/u/erroneousboat)\
**Post date:** [September 20, 2017, 1:56pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/9 "2017-09-20T13:56:33Z")

</div>

While trying to solve my problem, which resulted in the same error message as above, I stumbled upon this page. This is what I did in order to solve it. When adding the key like so:

```
bin/elasticsearch-keystore add-file gcs.client.default.credentials_file digaweb-c819f0854eae.json

```

be sure to set the client in your request, in this case the client is `default`.

```
curl -s -XPUT elk:9200/_snapshot/repository-gcs -d '{"type": "gcs", "settings": {"bucket": "repository-gcs", "client": "default"}}'

```

Source: [https://www.elastic.co/guide/en/elasticsearch/plugins/master/repository-gcs-usage.html](https://www.elastic.co/guide/en/elasticsearch/plugins/master/repository-gcs-usage.html)

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 27, 2017, 4:41pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/10 "2017-09-27T16:41:19Z")

</div>

I tried your way and gotten yet another error:

```
root@elk12:~/_# docker exec -it elasticsearch12 bin/elasticsearch-keystore add-file gcs.client.default.credentials_file 
/digaweb-c819f0854eae.json
root@elk12:~/_# docker exec -it elasticsearch12 bin/elasticsearch-keystore list
gcs.client.default.credentials_file
root@elk12:~/_# curl -u elastic:changeme -s -XPUT localhost:9200/_snapshot/repository-gcs?pretty -d '{"type": "gcs", "settings": {"bucket": "repository-gcs", "client": "default"}'
{
  "error" : {
    "root_cause" : [
      {
        "type" : "json_e_o_f_exception",
        "reason" : "Unexpected end-of-input: expected close marker for Object (start marker at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@687b81a1; line: 1, column: 1])\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@687b81a1; line: 1, column: 155]"
      }
    ],
    "type" : "json_e_o_f_exception",
    "reason" : "Unexpected end-of-input: expected close marker for Object (start marker at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@687b81a1; line: 1, column: 1])\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@687b81a1; line: 1, column: 155]"
  },
  "status" : 500
}
root@elk12:~/_#
```

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 27, 2017, 5:54pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/11 "2017-09-27T17:54:35Z")

</div>

I found a mistake, there was one _}_ missing at the end:

```
root@elk11:~/elastic/elasticsearch# curl -u elastic:changeme -s -XPUT localhost:9200/_snapshot/repository-gcs?pretty -d '{"type": "gcs", "settings": {"bucket": "repository-gcs", "client": "default"}}'
{
  "error" : {
    "root_cause" : [
      {
        "type" : "repository_verification_exception",
        "reason" : "[repository-gcs] path is not accessible on master node"
      }
    ],
    "type" : "repository_verification_exception",
    "reason" : "[repository-gcs] path is not accessible on master node",
    "caused_by" : {
      "type" : "google_json_response_exception",
      "reason" : "403 Forbidden\n{\n \"code\" : 403,\n \"errors\" : [{\n \"domain\" : \"global\",\n \"message\" : \"Insufficient Permission\",\n \"reason\" : \"insufficientPermissions\"\n }],\n \"message\" : \"Insufficient Permission\"\n}"
    }
  },
  "status" : 500
}
root@elk11:~/elastic/elasticsearch# 

```

I'm running _curl_ command off of master node though...

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [September 27, 2017, 11:19pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/12 "2017-09-27T23:19:20Z")

</div>

@alexus You need to check your google credentials/permissions. That error means Elasticsearch was not able to write a test file to GCS.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [September 28, 2017, 3:29pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/13 "2017-09-28T15:29:29Z")

</div>

I apologize, I actually ran commands in GCE environment and that's why it worked (well, sort of)), however when I run _curl_ command outside of Google Cloud environment, I'm still getting same error as I did before:

```
# curl --silent --request PUT elk:9200/_snapshot/repository-gcs?pretty -d '{"type": "gcs", "settings": {"bucket": "repository-gcs", "client": "default"}}'
{
  "error" : {
    "root_cause" : [
      {
        "type" : "exception",
        "reason" : "Error when loading Google Cloud Storage credentials file"
      }
    ],
    "type" : "repository_exception",
    "reason" : "[repository-gcs] failed to create repository",
    "caused_by" : {
      "type" : "exception",
      "reason" : "Error when loading Google Cloud Storage credentials file",
      "caused_by" : {
        "type" : "i_o_exception",
        "reason" : "The Application Default Credentials are not available. They are available if running in Google Compute Engine. Otherwise, the environment variable GOOGLE_APPLICATION_CREDENTIALS must be defined pointing to a file defining the credentials. See https://developers.google.com/accounts/docs/application-default-credentials for more information."
      }
    }
  },
  "status" : 500
}
# docker exec -it elk bash
# echo $GOOGLE_APPLICATION_CREDENTIALS
'/digaweb-c819f0854eae.json'
# /opt/elasticsearch/bin/elasticsearch-keystore list
gcs.client.default.credentials_file
# 

```

Please advise.

---

<div class="post-metadata">

**Author:** ![madsonic](https://avatars.discourse-cdn.com/v4/letter/m/8baadc/32.png) [@madsonic](https://discuss.elastic.co/u/madsonic)\
**Post date:** [December 2, 2019, 4:14pm UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/14 "2019-12-02T16:14:22Z")

</div>

I am getting this too. running v5.6 on EC2 instance

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 4:53am UTC](https://discuss.elastic.co/t/error-when-loading-google-cloud-storage-credentials-file/94370/15 "2022-11-04T04:53:34Z")

</div>


